UNC3753 is getting inside by turning the help process into the access path. The attacker does not need to beat email defenses if a worker can be talked into screen sharing or installing remote support software, because that hands over a live internal control channel that looks like legitimate IT help.
Mandiant ties the Jan–May 2026 campaign to UNC3753 and says it hit dozens of U.S. law, professional services, and financial firms. In many cases, the full sequence from first contact to data theft and extortion finished in one business day, and some searches and thefts started in under an hour. The stolen material included legal agreements, PII, and financial records.
The risk persists anywhere staff or the help desk will trust phone-based IT pretexts and remote management tools. This is broader than a normal phishing problem, because the attacker can work from inside the environment once the user opens the door.